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EXECUTIVE SUMMARY 


Ttie Federal Emergency Management Agency (FEMA) is cne focal 
point within the federal government for dealing with a wide 
spectrum of emergencies affecting the United States in peace 
and war. It has a central role in both domestic and national 
security emergencies ranging from natural and technological 
disasters through nuclear attacic. One of its mission areas 
falling midway on tne emergency spectrum is civil security. 

The organizational element of FEMA principally involved is tne 
Civil Security Division of the Office of Mobilization Prepared- 
ness under the National Preparedness Programs Directorate. A 
growing awareness of the functional dimensions and operational 
complexity of the mission made it increasingly apparent that 
existing information handling arrangements were inadequate, and 
that significant improvements were necessary if all of the 
diverse responsibilities of civil security were to be ful- 
filled. Accordingly, as part of a larger task to assist FEMA 
in developing an overall National Emergency Management System 
(NEMS), The MITRE Corporation was requested to give priority 
attention to a component sub-system of NEMS that would provide 
data and information management support expressly for civil 
security. The present report docxunents the results of this 
initial effort. 

Purpose and Approacn 

The basic tasx objective is to identify and define the informa- 
tion requirements of Che FEMA civil security mission. In order 
to reach that objective, specific answers are sought for cne 
following questions: 

o What are FEMA's responsibilities with respect to 
civil security? 

o What functions are performed to discharge those 
responsibilities? 

o What information is required to support each of cne 
functions? 

o What are the associated parameters and constraints of 
Che needed information? 

The analytically derived findings Chat answer these questions 
in detail are contained in Che body of the report. Salient 
highlights are summarized below. 
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FEMA Civil Security Reaponsibilities 

The scope of FEMA's civil security mission is broad. Ic covers 
a variety of measures to reduce the risks and potential con- 
sequences of disruption caused by deliberate acts of terrorism, 
civil disorder, sabotage, and subversioja. This includes 
responsibilities for mitigation, preparedness, response, and 
recovery - and the coordination of related activities among 
other federal agencies, the States and local governments, and 
nuioeroua private sector organizations. The mission is cast in 
a comprehensive time fraise: pre-event^ trans-event, and 

post-event. And it is concerned with the entire span of vital 
national resource systeias, such as, electric power, telecomr 
munications, transportation, food and water, governance, and 
public health. 

FEMA Civil Security Functions 

FEMA's civil security functions can be divided into three Droad 
time phases: (1) pre-event preparedness; (2) trans-event 

response; and (3) post-event recovery. A total of 26 essential 
functions has been identified througnout all three periods. By 
far the largest number, amounting to 13, is found in the 
pre-event preparedness pnase. These are on-going fxinctions 
performed on a continuing oasis under normal conditions. They 
include all those activities of a prudential nature undertaken 
in anticipation of any civil security incident prior to its 
occurrence. They are projected toward the future, with tne aim 
of enhancing prevention, mitigation, preparations for, response 
to, and recovery from such incidents should they materialize. 
These pre-event functions mainly address: threats and risks; 

policy, plans, and programs; coordination and liaison; legisla- 
tive and interagency matters; and training and exercises. 

Trans-event response functions focus on tne actual emergency at 
hand, and are therefore largely extempore, unique to a par- 
ticular event, and of relatively short duration. Depending on 
scenario circumstances, most are temporary, and some might be 
concurrent, truncated, or omitted entirely. Direct participa- 
tion by civil security staff personnel may be brief, confined 
only to the early stage until the FEMA response management 
principals can take over. Among the eight functions identified 
for this time phase, the major ones are: warning notification; 

providing various forms of decision support, including monitor- 
ing and assessownt; decision implementation and interim opera- 
tional coordination; plus initiating execution planning, 
mobilization, and readiness for recovery. 

The fewest number of civil security functions occur in the 
post-event recovery phase. They are oriented to ancillary 

vlll 


Declassified in Part - Sanitized Copy Approved for Release 2011/12/09 : CIA-RDP89B01330R000600870001-6 


Declassified in Part - Sanitized Copy Approved for Release 2011/12/09 ; CIA-RDP89B01330R000600870001-6 


support of those FEMA elements having primary responsibility 
for recovery management. Of tne five functions identified, tne 
most notable are: staff expertise and advice on residual 

threats and risks; special liaison regarding civil security; 
and drawing lessons learned from the emergency experience. 

Information Requirements to Support Civil Security Functions 
The foregoing civil security functions were tnen subjected to 
further analysis to determine the kind and extent of informa- 
tion required in order to perform tnem. The results of this 
analysis reveal that a total of approximately 145 major cate- 
gories of information is needed for all of the functions: some 

83 types are essential for the pre-event preparedness func- 
tions; 40 types during the trans-event phase; and 21 in the 
post-event recovery phase. Most of these information require- 
ments, moreover, are cast in generic terms, each category 
embracing a considerable breadth and depth of substantive 
concent. Much of tnat information, by its nature, has to be 
obtained piecemeal or in increments from many different 
sources, and tnen must be aggregated syncretically before it 
can be utilized. Clearly, the volume and variety of informa- 
tion demands posed by the civil security ftinctions imply a 
correspondingly sizeable and complex systems capability to 
acquire, process, and exchange the large quantities of data 
involved. 

Information Parameters and Constraints 

Finally, the functional information needs were examined at the 
next level of detail and cnaracterized in operational terms. 
Each requirement item was analyzed according to the following 
attributes: source, security classification, frequency, 

accessibility, and application. It was founo in the majority 
of instances that multiple sources must furnish the informa- 
tion; sometimes ten or more contributing agencies are 
involved. Security classification, even within a given infor- 
mation category, tends to run the gamut from unclassified 
through top secret, and often beyond into the compartmented 
levels. Frequency of need for infocmation, and of its updat- 
ing, ranges from hourly or daily to quarterly and annually, 
with many of the entries indeterminate because of scenario 
dependency . 

In general, tnose requirements pertaining to pre-event func- 
tions permit a more structured flow of information. There is 
usually less urgency and longer intervals between updates. 
During an actual civil security incident, however, the informa- 
tion processes are likely to change dramatically. In such a 
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craas-evenC pnase, cite need and currency are dictated by situa- 
tional imperatives tuat are innerently unpredictable — varying 
with the nature, scale, and pace o£ the emergency as it 
unfolds. For certain types of information, tne desired fre- 
quency, on both counts, then approaches real time. In the 
post-event recovery phase, the time-sensitivity of some infor- 
maton, though diminished, nevertheless remains relatively 
acute. Here again, frequency depends on the circumstances 
surrounding the recovery situation itself. 

FEMA’s access to the different types of Information may be 
routine, limited, or on an ad hoc basis, that is, only case by 
ease upon request. Overwhelmingly, throughout all three 
phases, accessibility of most categories should be routine, 
while roughly a fifth would be limited in one way or another, 
and about 10 per cent ad hoe. The last parameter was the 
application of tne required information when received, defined 
in terms of tmether it is used by and witnin FEMA or becomes 
part of an output product. Some of the information types fall 
into both classes. For all functions and information require- 
ments, the ratio between internal and output applications is 
found to be on the order of three to one. these output pro- 
ducts, however, are disproportionately critical, for they 
embody and articulate FEMA's civil security management role in 
practice. 
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1« INTRODUCTION 

At Che time of its establishment, in 1979, the Federal Emer** 
gency Management Agency (FEMA) was assigned responsibility for 
an "all hazards" approach to disaster mitigation, preparedness, 
response, and recovery in the United States. In carrying out 
this mandate, the Agency Cries Co provide the vital ingredients 
for comprehensive emergency management**-*spanning the full spec- 
trum from local disasters to nuclear war and extending through 
all levels of government and Che private sector. 

One of the vital ingredients in comprehensive emergency manage- 
ment is Che development of information systems designed to sat- 
isfy both Che mission requirements of FEMA as a whole and chose 
of its separate components. The basic goal that FEMA has sec 
for itself is Che establishment of a National Emergency Manage- 
ment System (NEMS) and its correlative integrated information 
systems architecture. In its efforts Co achieve this goal, Che 
FEMA management has requested the assistance of The MITRE Cor- 
poration, an organization Chat has specialized in the develop- 
ment and utilization of advanced information systems. As a 
part of this larger task, MITR£ was asked Co concentrate 
initial attention on one of FEMA's component missions— Che 
preparation for and response to maior civil security threats 
and incidents . The present report records Che results of this 
initial study. 

1.1 Purpose and Objectives 

The basic purpose of this study is to review the FEMA civil 
security mission requirements and to identify Che data and 
information needed to fulfill these requirements. More spec- 
ifically, the study is aimed at the following four questions: 
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o What are FEMA's responslbilitiea with respect to 
civil security? 

o What functions are performed to discharge those 
responsibilities? 

o What information is required to support these civil 
seenricy functions? 

o What are the associated parasieters and constraints of 
the information? 

The answers to these questions are documented in this report. 
Its concents present Che substantive findings and recommenda** 
tions resulting from Che study effort, and the product consti- 
tutes Che "Requirements Book” called for in the sponsor's 
statement of work. 

1.2. Scope 

The Scope of Che FEMA Civil Security Mission is quite broad, 
covering efforts to reduce the consequences of major acts of 
terrorism, civil disorder, sabotage, and subversion. It 
includes actions aimed at mitigation, preparedness, response, 
and recovery— and the coordination of these actions among 
Federal, State, and local govemments and numerous organiza- 
tions in the private sector of society. It deals with these 
actions in a comprehensive time frame: pre-event, trans-event, 

and post-event. And it is concerned with protection of the 
entire range of national resource systems — including all the 
lifeline systems (electric power, telecommunications, and 
transportation, as well as water, petroleum, natural gas, and 
waste disposal pipelines) and food, raw siaterials, industrial 
production, finance, public health, governance, and people 
(civil society). These various dimensions are taken into 
account in the subsequent analysis of the information func- 
tions, needs, and resources essential for the fulfillment of 
the FEMA civil security mission. 
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1.3 Approach 

The key members of the MITRE staff assigned to this project 
have had extensive previous contacts with FEMA and its prede-* 
cessor agencies and have drawn on this background of experience 
in formulating and conducting the present analysis. This 
previous experience provided basic knowledge of the structure 
and functions of FEMA. This basic knowledge was augmented and 
refined in a series of interviews with staff members of the 
Civil Security Division and other relevant FEMA components. 
These initial fact gathering interviews, in turn, were supple-* 
mented by reinterviews wherein the "straw sian" briefing tech- 
nique was utilized to test the applicability, relevance, and 
usefulness of the central ideas developed for this study. This 
involved the presentation of the conceptual framework and 
central ideas to key FEMA staff members and— based on several 
interactive iterations— the progressive refinement and elabora- 
tion of this conceptual framework and body of ideas. These 
data were further supplemented by an extensive and detailed 
review of mmerous documents pertaining to FEMA as a whole and 
to the responsibilities and mission of the Civil Security 
Oivis ion. 

1.4 Report Organization 

The subsequent chapters of this report are devoted to a 
detailed presentation of the analyses dealing with the FEMA 
civil security mission requirements and the corresponding data 
and information nunagement needs. Chapter 2 begins the anal- 
ysis with a review of the FEMA civil security aiission and with 
the notation that this analysis has broad applicability for 
other FEMA mission areas. Chapter 3 presents an analysis of 
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FEMA civil security funccioas ia relecion Co pre-evenc pre- 
paredness, crans-evenc response, and posc-evenc recovery 
phases* Chapter 4 details the types of information needed to 
support FEMA civil security functions during each of these 
three tiaie phases. Finally, Chapter 5 deals with various 
attributes of the needed infomation in terms of source, sec- 
urity classification, frequency of need and update, access- 
iblity, and application. 

Beginning in Chapter 3, the reader will note that an internal 
coding scheme has been incorporated into the text, figures, and 
tables. The contents of this report were reproduced, at the 
request of the sponsor, on a Wang word processor Diskette as an 
added product of the research effort. The code is based on an 
alpha-numeric key designed to facilitate machine access and 
retrieval of the substantive findings according to any pre- 
selected combination of system features and their related 
information properties. A detailed explanation of the key is 
presented below. 

The first element of Che code is a letter designating the 
respective time phase, as follows: "P", for Posc-evenc 

Preparedness; "T", for Trans-event Response; and "R", for 
Posc-evenc Recovery. The next element is an ordinal number 
corresponding to one of the discrete civil security functions 
perforated within a given phase; thus P.5 refers to Che fifth 
pre-event function. The third character ia a letter indicating 
Che particular information requirement associated with a 
specific function; thus T.4.B represents the second information 
requirement for the fourth trans-event function. The final 
element is a number in parentheses denoting one of the five 
parameters relating to a particular functional information 
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requirement. An example drawn from the report that illuatrates 
the full code would be R.2.C.(4), which translates into: R, 

the "Post-event Recovery Phase"; 2, the function cited is 
"Assess Continuing or Follow-on Threat:, C, the information 
requirement specified for that function is "Projected Risk 
Analysis Estimates"; and (4) the parameter of the required 
information pertains to "Accessibility". 
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2. FEMA CIVIL SECURITY MISSIOH 
2.1 Background 

Prior to Che formation of the Federal Emergency Management 
Agency, there was no mechanism for coordinating all civil 
security emergency planning, management, mitigation, and assis*' 
tance fuctions of the Federal Establishment. On August 23, 

1977, President Carter authorized a reorganization study of 
Federal emergency preparedness and response prograsis. A 
special task force of the President's Reorganization Project 
was established to review the then-current status of those 
programs and to recommend appro- priate organizational remedies. 

One on the principal foci of attention in this task force was 
the wave of hijackings, kidnappings, bombings, and assassina- 
tions around the globe that seemed to signal an increase in the 
frequency and violence of terrorism and other civil disorders. 
The final summary report of the President's Task Force on 
Federal Emergency Preparedness and Response recommended a com- 
prehensive reorganization by consolidating existing agencies 
and additional responsibilities into a single, independent 
Executive Agency accountable to the President and to Congress 
for all Federal mitigation, preparedness, and response activi- 
ties. Among the specific recommendations was one dealing with 
the Federal response to the consequences of terrorist incidents: 

Experts on terrorism charge that Federal organization for 
dealing with terrorist incidents is insufficiently compre- 
hensive. Specifically, they express concern over the lack 
of a focal point for coordination of the Federal response 
to meet such potential consequences of terrorist action as 
significant resource disruptions and physical damage. 
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The Project finds thst such a focal point is lacking, and 
reconmends that responsibility to coordinate vulnerability 
analysis and preparedness measures to mitigate the conse- 
quences of terrorism should be assigned to the new 
agency. (Task Force on Federal Emergency Preparedness and 
Response, President's Reorganization Project, Summary 
Report . Washington, D.C.: Executive Office of the 
President, June 19, 1978.) 

The consolidation of existing emergency preparedness and 
response agencies into a single new agency called the Federal 
Emergency Hanagement Agency was accomplished by Reorganization 
Plan No. 3, submitted to the Congress by President Carter on 
June 19, 1978. In his transmittal message, the President also 
noted that responsibility for the Federal response to the con- 
sequences of terrorist incidents— a new function not then 
assigned to any specific agency— would subsequently be assigned 
to the new Agency. That assignment was made in Executive Order 
12148, which charged FEMA with responsibility for "the coordi- 
nation of preparedness and planning to reduce the consequences 
of major terrorist incidents". That same Executive Order gave 
FEMA much broader authority for handling emergencies than 
existed in its predecessor agencies. The "all hazards" mission 
of FEMA is clearly stated in the following sections of that 
Executive Order: 


2-101. The Director of FEMA shall establish Federal 
policies for, and coordinate, all civil defense and civil 
esiergency planning, management, mitigation, and assistance 
functions of Executive agencies. 

2-102. The Director shall periodically review and 
evaluate the civil defense and civil emergency functions . 
of the Executive agencies. In order to improve the 
efficiency and effectiveness of those fxmctions, the 
Director shall recomuend to the President alternative 
methods of providing Federal planning, management, 
mitigation, and assistance. 
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2-203 . For purposes of this Order, "civil emergeacy" 
means any accidental, natural, man-caused, or wartime 
emergeacy or threat thereof, which causes or may cause 
substantial injury or harm to the population or substan- 
tial damage to or loss of property. (Executive Order 
12148, July 20, 1979.) 

Additional authority on the subject of civil security was given 
to FEMA in two other Executive Orders. Executive Order 10421 
provides for the physical security of facilities important to 
the national defense to include "security against sabotage, 
espionage, and other hostile activity and other destructive 
acts and omissions" not attributable to military defense or 
combat or to the dispersal and post-attack rehabilitation of 
facilities. The Director of FEMA is given broad authority to 
prescribe policies and programs governing activities of Federal 
agencies; developing and promulgating standards; assigning 
facilities to Federal agencies; approving or revising security 
ratings established by the Department of Commerce; reviewing 
physical security programs of Federal agencies; and keeping the 
President informed about the physical security of the facili- 
ties and furnishing him with appropriate recommendations. 

Executive Order 11490 consolidates the assignment of emergency 
preparedness functions to various Federal departments and 
agencies. The Director of FEMA is assigned responsibility for 
determining national preparedness goals and policies for the 
performance of emergency preparedness functions by Federal 
departments and agencies and in coordinating their performance 
with the total national preparedness program. FEMA also is 
directed to provide guidance to Federal departments and 
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agencies end co eveluace cneir emergency planning and prepared'- 
ness acCivitias. 

2,2 FEMA Civil Security Division Roles and Responsibilities 
Following tde establisbmenc of FEMA, cbese various autnorities 
and responsibilities were delegated to the Civil Security Divi- 
sion, located in the National Preparedness Programs Direc- 
torate’s Office of Mobilization Preparedness. The basic mis- 
sion of the Civil Sectirity Division is to coordinate the 
Federal Govemnunt's preparations for and response to civil 
security threats and incidents. This includes responsibilities 
for transforming national objectives and federal policy into 
planning guidance for the Federal Government's activities aimed 
at avoiding or mitigating the consequences of acts of ter- 
rorism, civil disorder, sabotage, and subversion. This 
involves requesting and receiving threat estimates; evaluating 
their impact on civil security programs; coordinating the 
production of vulnerability and consequence estimates for the 
various tareats; reviewing and coordinating the civil security 
planning development of the executive agencies; and performing 
periodic appraisals of tne government's civil security readi- 
ness posture. 

The major generic functions of the Civil Security Division — 
officially recognized by FEMA— include the following: 

o Conceptualizes and develops policy options for the 
Director of FEMA on the activities required to avoid 


'*'For other, more basic, authority on the civil security mission, 
see Pompan and Murray, A Practice Guide to the Legal Authorities 
for Reducing Widescale Consequences of Incidents Caused by 
Deliberate Manmade Acts . Washington, D.C. 1983. 
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or mitigate consequences resulting from acts of 
terrorism, civil disorder, sabotage, and subversion. 

o Prepares and promulgates Federal planning guidance to 
implement the approved policy. 

o Reviews existing authorities for civil security 

programs and recommends changes or new authorities , 
as appropriate. 

o Develops civil security programs and reviews Federal, 
State, and local government and private sector plans 
to avoid or mitigate the consequences of civil 
security incidents. 

o Coordinates the development of vulnerability and 
consequence estimates for each of the national 
resource systems (energy, transportation, food, 
etc.). Ensures that appropriate threat information 
is received and acted upon by other responsibile 
agencies. 

o Funds research relating to the mission and functions 
of the Civil Security Division. Develops procedures 
to ensure the exchange of civil security information 
between scientific and technical groups and Federal, 
State, and local agencies. 

o Recommends procedures for reviewing, evaluating, and 
improving the Federal Government's civil security 
preparedness. Prepares reports on the efficiency and 
effectiveness of the Federal civil security program 
for inclusion in the Director's annual report to the 
President. 

o Develops the "lessons learned" from incidents and 
exercises, and coordinates recommendations for 
necessary changes in policies and prograu. 

o In coordination with the Information Resources 

.Management Office, develops a management information 
system that will effectively support civil security 
objectives. 

o Represents the Federal Emergency Management Agency in 
meetings where civil security issues are discussed. 
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o F«rticip«tes with ocher FEMA componencs and oCher 
Federal agenciea in Che design and conduce of 
exercises Co CesC emergency procedures and plans for 
dealing wich civil securicy incidence. 

o Develops coordination procedures beCween Federal, 
Scace, and local govemmancs and Che private sector 
for the exchange of civil security informacion. 

2.3 Civil Security Information Management as a Microcosm 
These and ocher specific functions of Che Civil Securicy 
Division are subjected to detailed analysis in Che following 
chapter. Before Cuming to that analysis, however, it should 
be noted Chat the civil securicy functions of FEMA comprise 
only one segment of the cocal FEMA informacion management 
system. The analysis Chat follows focuses attention exclu- 
sively on Che civil securicy domain but should be viewed in a 
wider context of Che informacion support mechanism needed for 
Che conduce of all FEMA emergency management accivicies. 

Figure 2.1 depicts Che overall National Emergency ManagemenC 
Syscem (HEMS) and Che civil security mission wichin that sys- 
tem. The civil security domain comprises only one segment of 
Che larger NEMS. Despite certain unique features, ic can serve 
as a microcosm of similar information management requirements 
characterizing other FEMA mission areas. As a microcosm of the 
larger system, civil security shares the following characteris- 
tics with most of the other mission areas: 


o Tha actors involved in emergency mitigation, pre- 
paredness, response, and recovery plans, programs, 
and operations are numerous and diverse. As shown in 
Figure 2.1, they include the Preeident and the White 
Rouse Staff, other Federal Agencies, Che FEMA 
regions,, the States and local jurisdictions, and many 
agencies in the private sector. 
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o Th« audiences with whom FEMA must communicate in 

carrying out its missions are similarly numerous and 
diverse, both in terms of input and output 
information. 

o The types of information required pertain to func- 
tions in all emergency time phases— pre-event miti- 
gation and preparedness: trans-event response: and 
post-event recovery. 

o All activities oust be closely coordinated internally 
and externally— with both governmental and nongovern- 
mental ageheies. 

o Persons responsible for carrying out mission respon- 
sibilities must be prepared to act in both a routine 
and in an emergency or crisis mode. The sudden shift 
from routine planning activities to emergency opera- 
tions places a premium on organizational adaptiveness 
and flexibility. 

o Rish assessments and vulnerability and consequence 

analyses are essential in structuring mission activi- 
ties and in determining key informational 
requirements. 

o The national resource systems of civil security . 

concern (see Figure 2.2) are also of concern to all 
other qiission areas. They cover the gamut of ele- 
ments essential for societal survival and continuity 
and thus require continuing attention and protection. 

o Education and training programs, the conduct of tests 
and exercises, and the continuing critical evaluation 
of actual emergency operations are essential for 
achieving the requisite coordination of effort among 
relevant agencies and for developing an enhanced 
state of readiness. 

In the light of these similarities, the subsequent detailed 
analysis of the information needed for handling civil security 
functions can be viewed as a prototype for studying other FEMA 
mission areas and for developing the overall architecture of 
the FEMA National Emergency Management System. 
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3. ANALYSIS OF FEMA CIVIL SECURITY FUNCTIONS 

Inherenc in the broad scope of the civil security mission is a 
wide variety of roles played by FEMA. Most of these roles are 
of complex dimensions, some with many ramifications. The fol'~ 
lowing analysis, identifying the different kinds of component 
activities that must be carried out, reveals the range of dis*' 
Crete functions essential to accomplishing one or another 
aspect of the overall mission. Not every function, by any 
means, is actually executed by the Civil Security Division 
alone. Many are performed by or with substantial assistance 
from other FEMA staff elements, or by other Federal agencies or 
even the States and local jurisdictions. The role of the Civil 
Security Division is one of initiation, coordination, over- 
sight, and general orchestration, to ensure that all of the 
functions are in fact fulfilled. 

3.1 Functional Overview 

A salient feature of the civil security mission is the sheer 
number of functions involved. Depicted schematically in Figure 
3.1 is a macro-view showing the total functional universe of 
FEMA civil security. It is intended to be comprehensive and 
embraces the full spectrum of major functions to be performed 
throughout the successive stages of Che entire management 
process relating to the civil security mission area. 

The functions displayed are arranged in successive groups from 
left to right slong the horizontal axis according to three time 
frames. Those appearing in the first, or pre-event prepared- 
ness phase, are generic functions performed on a continuing 
basis under conditions of normalcy. They are of a contingency 
nature and include all conceivable preparatory measures thet 
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might be taken in anticipation of any civil security incident 
prior to its occurrence. Those grouped in the second time 
frame, the trans-*event response phase, are the ad hoc 
emergency-specific functions performed in real time when such 
an incident actually happens. Triggered by the event itself, 
they are acute, usually compressed in time, and, depending on 
scenario circwstances then prevailing, may be of relatively 
short duration before giving way and melding into the functions 
of the next phase. This last set, associated with the 
post-event time frame, marks an indefinite period. It repre- 
sents those ancillary civil security functions attending the 
restoration and clean-up operations to recover from the conse- 
quences of an incident. The basic dynamics of this three-stage 
process can be viewed as a single grand cycle closing upon 
itself, one where the last function links again with the very 
first. 

Within each time frame, the functions are also arrayed 
generally in descending order along the vertical axis. The 
sequence, however, reflects logical relationships as much as 
chronology. There is considerable overlap among them. Some of 
the functions are performed concurrently, while oiany others 
generate feedback affecting preceding ones. Together they form 
a coherent continuum that unfolds more or less incrementally as 
shown. This, however, may not always be the ease. Under some 
conditions, the sequence of functions may be compressed, trun- 
cated, or inverted. Discussion of the individual functions 
thesMelves will be deferred to subsequent sections immediately 
following. There, each function is described in detail for all 
three time phases in turn. 

As shown in Figure 3.1, there is an obvious time-skewed pattern 
to the functional distribution. Overwhelmingly the greatest 
number of functions take place during the first, or pre-event 
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preparedness phase* The number diminishes markedly in Che 
second, or Cran8*~evenC phase. By far Che lease are found in 
Che final, or posc-evenc phase. The explanacion for che 
decrease is ChaC once such an emergency has macerialized Chere 
are few civil securicy^nique funecions remaining. On a 
majorlcy of occasions Che response and recovery demands con-* 
froncing FEMA are likely Co be liccle differenc from Chose 
posed by similar disrupclons irrespecCive of cause. The conse- 
quences of a cricical bridge collapsing, for ezampla, are 
fundamenCally Che same vheCher Che resulc of CerrorisC demoli- 
tion, natural disaster, or accident. Most management func- 
tions, therefore, would devolve upon appropriate elements of 
FEMA normally responsible for recovery activities in Che after- 
math of any emergency situation. Civil security considerations 
Chen become peripheral compared to Che main task of recovery 
itself. 

3.2 Pre-event Preparedness Functions (P) 

The pre-event phase is a continuous on-going process that 
includes all of FEMA's management activities addressed to 
future civil security contingencies. The object is to enhance 
prevention, mitigation, preparation for, response to, and 
recovery from such incidents before they occur. Figure 3.2 
identifies the specific types of functions involved. Each is 
described in further detail in the sections below. 

3.2.1 Tasking the Providers of Threat Assessaiencs (P.l) 

The process begins with threat. FEMA is not in Che intelli- 
gence business, but is a user of finished threat assessment 
products obtained elsewhere. It relies on external inputs from 
Che intelligence community and other sources to acquire the 
needed assessments, as well as updates and amplification. For 
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civil security purposes, the tfireat information derived from 
sources outside FEMA may be regarded as strategic intelli- 
gence. It serves as the premises. on which most of the 
pre-event functions are predicated. 

The first function (P.I), accordingly, is the tasking by FEMA 
of those organizations that are in a position to supply threat 
assessment information. This presumes that prearranged autho- 
rity to do so exists. The tasking may be in the form of 
requests for formal estimative products analagous to a National 
Intelligence Estimate (HIE), but dealing with civil security 
threats, or to a Special National Intelligence Estimate (SNIE) 
focusing on a particular aspect of a given threat. In addi- 
tion, FEMA might also levy standing requirements cast in a form 
similar to Essential Elements of Information (EEI) to guide 
those who acquire threat information. Provisions must also be 
made for periodic, spot, and by-exception reporting of signi- 
ficant new items bearing on the threats as they develop. 

3.2.2 Synthesis of Available Threat Assessment Products (P.2) 
The second function is one of aggregation, collation, and 
integration of the threat assessment information coming from 
multiple external sources. It has to be organized and inter- 
preted into a master current assessment expressly tailored to 
the needs and interests of civil security. For a full appre- 
ciation of the threat, common patterns must be recognized, 
trends inferred, and forecasts extrapolated. These second 
order implications are the driving factors that determine how 
and where the threat intelligence should be exploited to 
enhance national civil security. They motivate and shape all 
aspects of preparedness. 
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3.2.3 Risk Analysis (P.3) 

Based on Che threat assessments, Che next function is to 
analyze what they mean insofar as risks posed for national 
resource systems. All that is known about a given threat has 
to be matched against the resource systems that it might 
disrupt. Then, each such combination of threat vs. system must 
be exasiined in terms of: 

o Types of targets likely to be struck 
o Probable attack mode employed 

o Vulnerability and susceptibility of Chose targets to 
such attack 

o Potential consequences expected or possible if Che 
postulated threat action succeeds. 

Each of Che above dimensions of risk analysis constitute major 
subfunctions in their own right. Many of them, however, would 
be performed in large part by others in coordination with the 
FEMA Civil Security Division. 

3.2.4 Policy Development for Civil Security (P.4) 

One of the most important functions is formulating national 
policy with respect Co civil security matters. Since the civil 
security community is so large and pervasive, with many dif- 
ferent participating agencies, echelons of jurisdiction, and 
private sector organizations involved, there is need for a 
coherent and comprehensive body of U.S. Government policy 
establishing common national aims and priorities. A concomi- 
tant of setting policy goals is allocating roles, missions, and 
authority governing who is assigned which tasks and objectives, 
along with defining the responsibilities and prerogatives 
attendant thereto. The function of FEMA in this regard is Co 
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help initiate, develop, and coordinate such national civil 
security policy, and once adopted, to promulgate and implement 
it. The function applies equally to amendment or amplification 
to existing policy. 

3.2.5 Planning Guidance (P-5) 

This function is essentially the issuance of strategic direc- 
tion and terms of reference for the development of civil secu- 
rity plans or annexes to plans. Central management at the 
national level is necessary to ensure that the resulting family 
of plans is compatible and the plans reinforce one another. 

The guidance stems largely from the preceding policy function. 

Depending on the agency concerned, the plans to be dravm can 
pertain to any phase or aspect of civil security operations, 
from prevention and mitigation, through preparedness, to 
response and recovery. FEMA, besides levying the requirements 
for such planning, provides the concepts and premises on which 
it will be based, outlines the doctrinal principles its sub- 
stance should reflect, and establishes criteria and standards 
to be met. Other instructions may also be given, such as 
identifying critical areas where planning coordination is 
needed between agencies. 

3.2.6 Plans Review and Evaluation (P.6) 

Effective preparedness requires quality assurance of civil 
security plans. A mosaic of separate yet interrelated plans 
must be produced by the various Federal departments and 
agencies, by the States and localities, and by private sector 
organizations. They would differ in content, purview, and 
application* An important FEMA function, therefore, is to see 
to it that, individually and collectively , these plans take into 
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account and adequately provide for every contingency need 
oearing upon civil security. 

The first step is determining vnetner required plans exist, and 
if so, their status. They must then be reviewed for compliance 
with current policy and FEMA guidelines, and be evaluated from 
the viewpoints of completeness, currency, appropriateness, and 
feasibility. Missing plans must be developed, and any gaps, 
problems, or conflicts within or between plans must be recon» 
ciled. The function is essential to a sound planning struc- 
ture, national in scope and accommodating all civil security 
requirements wnatever the action level or scenario circumstance. 

The large number of plans involved will undoubtedly require the 
delegation of a portion of this function, such delegated 
review and evaluation, as well as the major planning products 
that result, would oe subject to oversight by FEMA. 

3.2.7 Program Coordination (P.7) 

The program coordination function is multidimensional and 
complex. It may oe regarded as a set of parallel but sepa- 
rately perfoxnaed functions. There is virtually an unlimited 
number and variety of potential programs, or distinct program 
increments, to contend with, though not all are being actively 
pursued at present. They can range the gamut of preparatory 
measures directed toward reducing vulnerability, improving 
response capability, or lessening the disruptive consequences 
when an incident occurs. Characteristically, many participants 
are involved in implementing them. The national focal point 
for coordinating and managing all such prograais is FEMA. 
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Physical Security is a broad program area coataiaing several 
major components. It embraces prevention, protection, and 
safeguards against disruptive acts. The measures and means are 
designed to deter or preclude successful attack, or to counter 
and defeat it if attempted, llluatrative examples, either 
currently underway or projected, are: 

o Emplacement of barriers and periaieter fences 
o Surveillance devices and alarms 
o Patrols 

o Tactical teams to eliminate or neutralize threats 

A complementary program area is hazard reduction, such as con** 
cealment or hardening of sensitive facilities and critical sys" 
tern elements. An example might be to put emergency operations 
centers underground, or to install failsafe equipment, such as 
automatic sprinklers wherever flammable or volatile’ substances 
are concentrated. Another closely related program pertains to 
damage limitation and mitigation of immediate effects stemming 
directly from an attack. This could be, for example, redundant 
or backup facilities, modular configuration and dispersed sit- 
ing of components, or containment features to minimize collat- 
eral damage, the latter is extremely important for certain 
inherently inviting and exposed targets where any initial 
destructive impact is likely to be escalatory, triggering wide- 
spread chain reactions. A case in point is POL tank farma— or 
storage depots for explosives. These attractive, high-value 
targets of opportunity, particularly if located within or in 
proximity to congested urban and industrial centers, call for 
special program attention on civil security grounds alone. The 
program could, among other things, encourage construction codes 
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requiring revetmencs and levees around such installations, or 
zoning ordinances to isolate them geographically. 

Other programs are oriented mainly to enhancing the civil 
security infrastructure and its capacity to respond. They 
provide for better organization and training, upgraded facili-* 
ties, and acquisition of necessary resources, including person** 
nel, equipment, and supplies. A more general program area of 
FEMA that has direct utility for civil security purposes is the 
development of direction and control mechanisms at every 
response level. This applies particularly to telecommunica- 
tions and information management systems. An additional 
response program, though not formally defined as such, 
emphasizes emergency action procedures, which apply to civil 
secxirity emergencies in common with other types. There is also 
currently underway a program covering all aspects of civil 
security relating to maritime ports. It represents in micro- 
cosm Che entire civil security mission. Presumably other 
analagous applications programs will follow. 

In sum, program coordination is a constellation of functions, 
each keyed to its respective program. It may be expected that 
over time the total agenda of civil security programs under 
FEMA purview will expand. 

3.2.8 Initiate Proposed WSC or Legislative Action (P.8) 

As the civil security environment evolves and policies and 
strategy change, there will be need for new authority, modifi- 
cation or clarification of existing charters, or other basic 
institutional adjustments regarding the civil security struc- 
ture and process. At issue might be jurisdictional ambiguity 
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or scacutory constraints impading FEMA's civil security mis- 
sion. Initiating, coordinating, and advocating such proposals, 
whether to be acted upon by the Executive Branch at the White 
House level or by Congress, is a function of the FEMA civil 
security staff. It is the Agency's organizational element 
having the relevant expertise, subject competence, and respon- 
sibility. Thus, in conjunction with the legal counsel, it 
would, formulate, develop, and coordinate any proposed execu- 
tive orders, directives, or laws affecting its sphere. This 
includes preparing the supporting rationale and testimony to 
justify the proposed action before the National Security 
Council or Congressional committees. By extension, the func- 
tion also includes similar staffing vis-a-vis regulatory boards 
and commissions . 

3.2.9 Advisory Assistance (P.9) 

Advising the civil security community is a general function. 
Advice might be requested or volunteered, and could cover a 
wide range of topics. One specific area would be technology. 
FEMA is in a unique position to serve as the central clearing- 
house for maintaining and exchanging technical information 
regarding civil security. As part of its responsibilities in 
this mission area, it could advise all parties concerned on 
current and emerging technical developments with respect to 
threat capabilities, such as new explosive devices and toxic 
agents or sophisticated new skills and techniques employed in 
perpetrating terrorist acts or sabotage. On the other hand, it 
could also advise on developments in technology designed to 
thwart threats, such as new penetration sensors and surveil- 
lance devices or new methods of fire suppression and bomb dis- 
posal. In addition, advice might also be provided on new 
vulnerabilities being incurred in national resource systems 
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because of technological advances, such as the introduction of 
sensitive and critical control equipment. 

None of the above excludes other, more basic kinds of advisory 
assistance. This could be in the form of recommended organiza- 
tional and procedural solutions for dealing with local problems 
or special circumstances. 

3.2.10 Liaison with Federal Agencies. States, and Private 
Sector Organizations (P.IO) 

The liaison function is essential for establishing and main- 
taining rapport with the civil security community at large. 

The purpose and scope are broad and flexible, rather than cir- 
cumscribed. It is performed through informal dialogue directly 
between the FEMA civil security staff and counterpart elements 
of key agencies and, at times, selectively with state officials 
and with certain private sector organizations having a major 
role in the national resource systems. The mutual exchange of 
information allows FEMA to keep abreast of what is happening 
throughout the community and to recognize latent or emerging 
problems and opportunities that might not otherwise become 
apparent. Conversely, members are apprised of developments 
elsewhere that may have implications for them. Such open 
channels promote cooperation generally, and when occasion 
demands, can facilitate coordination to deal with specific 
matters of immediate concern. 

3.2.11 Represent FEMA on Interagency Civil Security 
Committees (P.ll) 

At any given time there are a number of interagency committees, 
panels, and task forces set up to address civil security 
issues. One 'of the functions of the FEMA civil security staff 
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is to serve as the agent of FEMA, presenting its views, posi- 
tions, and recommendations in. the deliberations of these 
groups. This function includes performing all the staffing 
preparations and coordination, both internally within FEMA as 
well as externally with other agencies affected and other 
interested parties. It may involve extensive interactions with 
many levels of FEMA's civil security constituency, at the 
Federal, State, local and private sector levels Achieving con- 
sensus beforehand on controversial points could be critical to 
the favorable outcome of such interagency proceedings. 

3.2.12 Training. Tests. Exercises, and Gaming Support (P.12) 
This function refers to a standing requirement to provide 
special expertise in support of, or to participate in, any 
training, tests, exercises, and simulation gaming wherever 
civil security is involved. It could include assisting in the 
development, planning, or conduct of such activities, as well 
as managing their execution and evaluating the results. What 
the function consists of and how it is performed, therefore, 
vary considerably insofar as the kind and extent of demands 
placed on the FEMA civil security staff. 

3.2.13 Periodic Strategic Net Appraisals of Civil 
Security (P.13) 

From time to time, FEMA must produce strategic net appraisals 
of the state of the nation's civil security. Basically the 
function is overall assessment of conditions with respect 
to threat, vulnerabilities, and capabilities. Included would 
be an estimate of the threat climate in terms of its current 
level, salient characteristics, and perceived trends. A cor- 
relative estimate would address significant vulnerabilities 
presently existing in national resource systems, their suscep- 
tibility to attack, and the disruptive effects likely to 
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ensue. There would also be an accompanying estimate of civil 
security capabilities, posture, and readiness to cope with the 
threats, along with vulnerability reduction measures underway 
or planned. Finally, summary conclusions would be drawn as to 
the prospects for responding to such emergencies and recovering 
from their potential consequences. The function provides a 
vital service, not only in support of senior executives and 
decisionmakers, both in FEMA and the Administration, but also 
may have value for Congress and the public. 

3.3 Trans~event Response Functions (T) 

The trans~event response phase commences when a threat autte** 
rializes and a civil security incident occurs. By definition, 
it focuses on the event at hand and, therefore, the functions 
are ad hoc, performed in real time, and are emergency- 
specific. Figure 3.3 presents schematically a description of 
the major functions carried out during this phase. 

normally the functional sequence would be triggered abruptly by 
the first awareness by FEMA that something has happened relat- 
ing to civil security. However, as the dotted area appearing 
in the Figure 3.3 diagram ii^dicates, there may sometimes be 
advance tactical warning that an event is imminent , thus pro- 
viding lead time. The functions would then begin immediately 
upon receipt of such warning. 

It should be noted that the duration and extent of civil 
security involvement is scenario-dependent. On most occasions 
it is expected to be relatively brief, lasting only until the 
regular FEMA apparatus for response management is marshalled 
and can take over. Hence, the civil security staff may not be 
directly involved in all of the functions listed. 
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FIGURE 3.3 

TRANS-EVENT RESPONSE FUNCTIONS 
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The individual functions are discussed in the sub**sections 
immediately following. Selected details explain and amplify 
each 'of them in turn. 

3.3.1 Verification of Occurrence (T.l) 

The essential first function is to verify that a reported civil 
security incident has indeed occurred. A vital component of 
that function is establishing basic facts: what happened, 

where, and how serious does the event appear to be?. Initial 
characterization and sizing estimates are critical as to 
whether many of the subsequent steps should be taken. The 
report could be a false alarm, or the incident may be only of 
local significance. On the other hand, a seemingly trivial 
event may be seen from the national perspective as bearing the 
seeds of a major emergency* 

3.3.2 Warning and Alerting Notification (T.2) 

The next function is a crucial one. All of the agencies, 
officials, and watch centers having a direct need to know must 
be warned chat an emergency exists* Among those to be immedi** 
ately notified, for example, would be the FEMA Emergency Infor- 
mation Coordination Center (EICC) and Che Director and senior 
executives of FEMA, the White House Situation Room (WHSR) , Che 
National Military Command Center, the FBI operations center, 
other relevant departments and agencies, and perhaps certain 
State governments. Also Co be alerted as a second priority 
would be Chose agencies and organizations likely to be affected 
in one way or another by Che event or its aftermath. This 
could include private sector elements, such as the transporta- 
tion carrier industry or telecommunications companies. 
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3.3,3 Decision Support (I. 3) 

A vital function of the trans-event phase is the multifaceted 
one of providing decision support* which shapes the kind of 
operational response that is taken in connection with the inci- 
dent. The function consists of its own sequence of functional 

e 

steps. As outlined in Figure 3.3* the series of cosqionent 
sub-ftmetions comprises the following: 


o Initial assessment of the emergency event in terms of 
immediate casualties and damage incurred* based on 
the information available 

o Estimated direct impact on national resource systems 
and projected consequences, including the probable 
scope of disruptive effects* their severity* and 
duration 

o Monitoring the current situation on scene and 
updating status changes, along with analysis of 
reported information 

o Monitoring the current response-reaction operations 
underway on scene to cope with the incident 

o Preliminary estimates of resources required to 
respond to the event 

o Briefing decisionmakers in FEMA and senior executives 
of the Administration on the facts and implications 
of the event 

o Developing strategy options and proposed courses of 
action to deal with the emergency 

o Recomsiending augmentation of the EICC and activation 
of FEMA emergency action teams to manage response 
activities. 


3.3.4 Decision Implementation Action (T.4) 

This function sets in train the course of action adopted. It 
involves preparing and issuing orders and instruction tasking 
all of the agencies and organizations responsible for carrying 
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out the response operations decided upon. The function is 
tiae*-sensitive, and different kinds of instructions may have to 
be given to many agencies. 

3.3.5 Interim Coordination of Immediate Emergency Action (T.5) 
In the interim, before the full response is implemented, some 
urgent crisis actions of immediate priority may have to be 
executed as soon as possible. These could be, for example, 
rescue and evacuation operations to save lives, damage control 
to prevent the situation from getting out of hand and turning 
into a large-scale catastrophe, and a variety of other efforts 
to preserve life and property. The function of coordinating 
such immediate actions at the outset of the emergency may 
temporarily have to be performed by the FEMA civil security 
staff. 


3.3.6 Initiate Execution Planning. Asset Mobilization, and 
Readiness for Recovery (T.4) 

Another function that civil security may temporarily have to 
perform is to begin preparations for recovery operations. 
Depending on the scenario, delay night prove costly. The func- 
tion could include getting execution planning started, seeing 
to it that mobilization of necessary manpower and resources is 
underway, and initiating an appropriate state of readiness 
generally. Again, a considerable number of agencies and organ- 
izations might be involved. The staffing and coordination task 
would be correspondingly large and subject to time pressxires. 

3.3.7 Congressional and Public Affairs Dpdate (T.7) 

In any emergency there is always a great desiand for information 
from many quarters. In collaboration with the EICC, the civil 
security staff would input that information, through briefings 
and status reports, to the FEHA Congressional relations staff 
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and Che public affairs office. Tbe latter would process and 
release it tarough tueir own cdaxmels to their respective 
audiences. The FEMA civil security staff would not itself deal 
directly with the news media or members of Congress. 

3.3.8 Hand-off and Transition to FEMA Response Management 
Principals (T.8) 

This function marics the termination of civil security's direct 
role in response management. Presumably at this stage, FEHA's 
regular response management principals would be actively taking 
over and in charge. The transition could come quite early in 
the emergency — indeed could be the first step taken in tne 
trans-event period. As soon as the hand-off was effected, 
civil security would retire to tne background and enter into 
the next pnase, where its post-event recovery functions become 
relatively peripheral to the main stream of FEMA activity in 
relation to the emergency. 

3.4 Post-event Recovery Functions (R) 

In tne final phase, during post-event recovery, civil security 
is relegated to a subordinate role. Relatively few functions 
tnat are uniquely of a civil security nature remain to oe 
performed. Most of the recovery responsibilities fall in otner 
mission areas of FEMA, and the civil security staff is more or 
less on standby, though it does provide certain ancillary sup- 
port to recovery manageaiant . Depending on scenario, some of 
these residual functions can nonetneless be important and of 
considerable scale. Figure 3.4 depicts the sequence of typical 
post-event recovery functions expected to be performed. Each 
is discussed in further detail in the subsections below. 
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(R) POST-EVENT RgCQVFRY 
(Ancillary Manasehcnt Support Functions) 


R.l Assist FEMA EICC and Staff Elements 

- Provide CS Staff Expertise, as Required 

- Maintain Liaison with Civil Security Cohhunity 

R.2 Assess Continuins /Follow-on CS Threat 

- Risk Analysis (Other Targets. Vulnerability. 

Consequences) 

- Advise All Concerned (Intra-FEMA and External) 

R.3 Mdnitor Recovery Phase Activities/Prosress 
(Apprise Interested Agencies) 

R.H Develop After-action lessons Learned 

- Substantive Problems Encountered 

- Systems Dysfunctionalities Experienced 

R.5 Reappraise /Adjust Policy, Plans. Programs 


FIGURE 3.4 

POST-EVENT RECOVERY FUNCTIONS 
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3,4.1 Assist FEMA SICC and Staff Elementa (R.l) 

A po8t-*event function performed on a suaCained basis is to pro- 
vide timelj specialized staff support regarding civil security 
matters to the EICC, the Office of Emergency Operations (OEO), 
and other eleownta of FEMA whenever such ei^ert assistance is 
required. Many of the recovery operations can have significant 
civil security implications, and recovery management must take 
these considerations into account. Another aspect of the same 
function is siaintaining active liaison with those agencies and 
organizations of the civil security community that may have 
continuing interest in the emergency event or may be affected 
by or have a role in recovery. An example would be law 
enforcement to prevent looting, or to cordon off dangerous 
areas. Much of the necessary coordination of this kind could 
be accomplished via such specialized liaison between the civil 
security staff and other groups involved in the recovery 
process. 


3.4.2 Assess Continuing or Follow-on Threats (R.2) 

A given emergency event confronting FEMA may be only one in a 
series of incidents, or part of a concerted larger campaign of 
threat actions to follow. Accordingly, an essential civil 
security function is intensive risk analysis to identify other 
vulnerable targets that might be affected, and also to estimate 
the likely consequences if these too were to be struck. In 
some senarios, this could be an extended iterative process 
requiring interaction with many agencies and organizations. 

The products of the riskranalysis function would be dissemi- 
nated to all concerned, within FEMA and externally. The 
resulting alert notification might prove critical to those in 
charge of security for the national resource systems in 
particular. 
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3.4.3 Monitor Recovery Activities and Progress (R.3) 

In the post'event phase, this function would be a continuation 
of the earlier monitoring of the emergency situation, but on a 
more summary level, and tracking the general progress of 
recovery operations. It would be performed derivitively, based 
on the primary monitoring being done by other elements of 
FEMA. The object is for the civil security staff to keep 
itself abreast of developments, and for it to apprise all other 
interested parties in the civil security community on the 
status of recovery. 

3.4.4 Develop After-action Lessons Learned (&.4) 

The experience gained in the course of the event offers a 
unique opportunity for drawing lessons that can be of great 
value for future emergencies. An important civil security 
function, therefore, is to reconstruct what happened, based on 
its active involvement, and see what can be learned. Evidence 
must be gathered and analyzed relating to all aspects of the 
emergency, from mitigation and preparedness prior to its occur- 
rence through response and recovery. Things to look for would 
be problems encountered, both substantive and procedural. 
Attention should be given to identifying achievements as well 
as deficiencies, with special emphasis on systems performance. 
Structural dysfunctionalities may be revealed that sdght other- 
wise not be detected. Existing policy, plans, and organization 
can also be examined for adequacy and appropriatness. The 
potential benefits of such post mortem evaluations should be 
exploited to the fullest. 
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3,4,5 Reappraise and Adjust Policy. Plans and Prograaa (R.5) 
Th« final post-^venc function is the feedback that closes the 
loop, leading again to the. pra-^vent phase. In light of the 
lessons derived from the previous function, the FEMA civil 
security staff is now in a position to reappraise and, where 
necessary, adjust, refine, or amplify policy, plana, programs, 
and all the other functional components of its mitigation and 
preparedness mission. The kind and extent of adjustment 
resulting from this last function would depend on the nature of 
the event just concluded and the significance attributed to 
that experience. 
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4. INFORMATION REQUIRED TO SUPPORT FEMA CIVIL SECURITY FUNCTIONS 
An essenCial step in the development of any operational infor-* 
mation system is the translation of organizational functions 
into the types of information required to fulfill these func* 
tions. This chapter identifies the information needed to 
support the pre-event, trans-event, and post-event civil 
security functions discussed in the previous chapter. 

4.1 Glasses of Information toquirements 

Figure 4.1 briefly outlines the major classes of civil security 
information requirements by time phases. These and other more 
specific information requirements will be discussed in greater 
detail in the subsequent sections. 

4.2 Pre-event Information Needs 

Identifed in this section are the categories of information 
required to fulfill the essential civil security functions 
during the pre-event mitigation and preparedness phase. 

4.2.1 Tasking the Providers of Threat* Assessments (P.l) 

To acquire threat assessment products and other essential ele- 
ments of information (CEIs), FEMA must have the authority to 
levy information requirements ' oh relevant agencies and organi- 
zations in the intelligence community. Correspondingly, Civil 
Security Division personnel must be fully cognizant of the 
various statutes, executive orders, and memoranda of under- 
standing that give them this authority. But the possession of 
this authority is not sufficient to ensure that the threat 
information will be obtained. In addition, civil security 
personnel must be fully aware of the range and types of threat 
data that can be made available to FEMA. This requires the 
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naiacenance of point-of'*coatacc rosters for the primary iatel* 
ligence, security, and law eaforcemeat agencies, both public 
and private. It also requires a set of standard operating pro- 
cedures (SOPs) for guiding the query-response transactions 
involved in gaining access to the relevant data bases. Thus 
the key information requirements for this function are as 
follows: 

P.I.A Existing FEMA Authority for Levying Threat EEIs 
(Statutes, Executive Orders, Memoranda of 
Understanding) 

P.I.B Koster of Threat Assessor POCs (Intelligence 
Community and Others) 

P . I . C Query-Response SOP s 

Where the authority for levying threat EEIs does not exist, 

FEMA must initiate the necessary action to establish such 
authority (see section 4.2.8). 

4,2.2 Synthesis of Available Threat Assessment Products (P.2) 
The variety of sources that must be tapped in formulating 
threat assessments is illustrated in Figure 4.2. This shows 
that a coverage of threats to the various national resource 
systems requires contacts with over 30 other Federal agencies 
in addition to the intelligence community at large. Thus one 
of the difficult tasks that the FEMA Civil Security Division 
must perform is to collate and synthesize many different BEI 
inputs in developing its threat assessments. The following 
categories of information are needed to fulfill this function: 

P.2. A Source of Threat (Identity and Nature) 

P.2.B Historical Profile (Objectives, Organization, 
Linkages, Support) 
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P.2.C Method(s) of Operation (Tactics, Targets, Time 
Frames) 

F.2.D Capabilities (Deployable Strength, Technical 

Skills, Resources) 

P.2.E Geographic Data (Base of Operations, Staging 
Points, Pre-positioned Assets) 

P.2.F Recent Activities (Type, Periodicity, 

Pattema/Tcends) 

P.2.G Bxtrapolation/Forecasts of Possible Threat Action 

The complexity Involved in this process is further illustrated 
in Figure 4.3. It shows, at the next level of detail, the 
major categories of data needed for these threat assessments, 
including some of the key data elements that must be taken into 
account in the evaluation of the threats. 

4.2.3 Risk Analysis (P.3) 

The development of risk analyses is a complicated process. It 
requires the mobilization of data on current civil security 
threats, and on the national resource systems at risk and their 
interdependencies. It also requires data on the likely targets 
for disruption, on the likely modes of attack, on the vulner- 
ability of various targets, and on the potential consequences 
of an attack in terms of primary and secondary effects, seve- 
rity, scope, and duration. The following information is needed 
to support this function: 

P.3.A Current Threat Assessment Data 

P.3.B National Resource System Descriptions 

(Structural Configuration and Operational 
Characteristics ) 

P.3.C Interdependencies among Systems 
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P.3.D Likely Target Types for Disruption, by System 
(Critical Nodes/Choke Points, Essential 
Elements, Key Personnel) 

P.3.E Applicable Attack Modes (Demolition, Arson, 

Seizure, Chemical/Biological, Etc.) 

P.3.F Vulnerability Appraisals (Target Accessibility, 

Exposure, Value vs. Attack Feasibility/ 
Probability) 

P.3.G Potential Consequences Estimates (Primary 

Impact/ Secondary Effects) - Severity, Scope, 
Duration 

Figure 4.4 expands on these requirements, showing some of the 
detailed information needed under each component for analyzing 
risks to the various national resource systems. Figure 4.5 
outlines a requirements model showing the kind of algorithm 
that can be used for such a risk analysis and postulates an 
example illustrating its application in a hypothetical case, 
namely, risks to bridges and tunnels in the railway 
transportation resource system. 

4.2,4 Policy Development (P.4) 

In its role as a developer and coordinator of policy, FEMA must 
be aware of relevant civil security issues that need policy 
resolution or clarification. This requires knowledge of admin- 
istration decisions, directives, and statements on goals, 
interests, and priorities. The sometimes overlapping Federal 
responsibilities, roles, and authorities (see Figure 4.2) must 
also be understood, and the views of interested parties must be 
solicited as input to any policy development. The following 
information requirements are encompassed in this civil security 
function: 
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INFOBMATION REQUIREMENTS FOR CONDUCTING RISK ANALYSIS 
OF NATIONAL RESOURCE SYSTEMS 
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P.4. A Administration' Statements/Decisions/Directives 

on National Civil Security Goals, Interests, 
Priorities 

P.4.& Nature and Background of Issue(s) Needing Policy 
Resolution or Clarification 

P.4.C National Resource System(s) Affected 

P.4.0 Agencies Involved 

P.4.E Statutory Imperatives and Constraints 

(Responsib^ities, Roles, Authority) 

P.4.F Relevant Existing Policy and Memoranda of 

Understanding 

P.4.G Views of Major Parties Concerned 

P.4.H Policy Implementation Requirements 

4.2.5 Planning Guidance (P.5) 

The Civil Security Division provides guidance in the develop- 
ment of plans for dealing with threats to the national resource 
systems. As the information requirements below indicate, this 
guidance must cake into account national strategies, the range 
of potential threats, and agency responsibilities and 
capabilities: 


P.5. A National Policy Posture (Administration 

Strategy, Concepts, Desiderata) 

P.5.B Statutory Mandates (Executive Orders, 

Legislative Authority) 

P.5.C Range of Potential Threats 

P.5.0 Vulnerabilities of Threatened National Resource 

Systems 

P.5.E Responsibilities Hierarchy/Network (Roles and 

Missions) 
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P.5.F 

Existing Plans, Memoranda of Understanding, 
Established Precedents 

P.5.G 

Capabilities and Limitations of Agency(ies) 
Involved 

P.5.H 

Resources Required, including Assets Aveilable 
from Private Sector . 

4.2.6 Plans 

Review and Evaluation (P.6) 


The Civil Security Division tekes en active role in the review 
and evaluation of the civil security plans of other agencies 
and organizations. Among the information needs in satisfying 
this role are: a point of contact roster of those personnel in 

the responsible agencies who developed the plans, ah identifier 
to locate the plan's custodian or repository, and an internal 
record of policy and guidance issued by FEMA regarding the 
respective plans. The information needs involved in this 


process are 

noted below: 

P.6. A 

Master Inventory of Civil Security Plans/ Annexes 
(Identity and Responsible Agency) 

P.6.B 

POC Roster of Agency Planners 

P.6.C 

Repository of Plan (Custodian) 

P.6.D 

Orientation of Plan (Mitigation, Preparedness, 
Response, Recovery) 

P.6.E 

Scope and Content (Summary of Provisions) 

P.6.F 

Status (Completeness, Currency, Tested/Untested) 

P.6.G 

Subordinate Related Plans (Regional/State/Local/ 
Private Sector) 

P.6.H 

Interrelationships Among Plans (Convergence and 
Dependencies) 
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P*6.I Internal Record of Policy/Guidance leaned by FEMA 

P.6.J Test/Exercise/Real-life Data on Plan Application 

4,2,7 Program Coordination (P.7) 

In addition to reviewing and evaluating plana, the Civil 
Security Oiviaion eoordixiatea Federel, State, local, and 
private aector prograaa relevant to ita miasion, Aa noted in 
the following liat, thia involvea the collection of information 
on relevant atatutea, azecutive ordera, and memoranda of under- 
atanding, the repertoire of mitigation, preparedneaa, reaponae, 
and recovery techniquea and technology in uae, and program 
implementation, atrategy, and achedulea: 

P.7.A Maater Liat of Civil Security Programa 

(Identity, Purpoae, Scope, Participating 
Agenciea) 

P.7.B Interrelationahipa/Dependenciaa Among Programa 

P.7.C Relevant Statutea, Executive Orders, Memoranda 

of Understanding 

P,7.0 Formal Steering Committees, Working Groups, 

Panels Involved (Standing and Ad Hoc) 

P.7.E Catalog of Major Program Components (Objectives,. 
Priorities, Milestones) 

P.7.F Responsibility Network for Each Program/Program 

Element (Federal, State, Local, Private Sector) 

P.7.G Roater of Program Managers, Action Officers, 
Cognizant Staff (POGs) 

P.7.H Repertoire of Mitigation, Preparedness, 

Response, and Recovery Techniques and Technology 

P.7.1 Program Implementation Strategy and Schedules 

P.7.J Resource Requirements (Manpower, Special Skills, 

Equipment and Supplies, Funding Assistance) 
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F.7.K Status o£ Programs (Progress, Delays, Changes, 
Problems) 

4.2.8 Initiate Proposed NSC/Legislative Action, as 
Warranted (P.8) 

In conducting its mission, the Civil Security Division may 
encounter problems, conflicts, and the need for additional 
executive or legislative authority. Based on the information 
requirements stated below, FEM4 may find it necessary to pro- 
pose and initiate National Security Council or legislative 
action to resolve these problems: 

F.8.A Nature and Background of Problem Needing such 
Remedy 

F.8.B Pertinent Existing Directives/Legislation 

P.8.C Internal Staff Views of Interested FEMA Elements 

F.8.D Opinions and Views from Other Affected Agencies 
P.8.E Legal and Political Considerations 

4.2.9 Advisory Assistance (P.9) 

A vital function to be performed by FEMA's Civil Security Divi- 
sion is to serve as a clearinghouse for information on threat 
technologies and vulnerabilities and the corresponding security 
technologies needed for dealing with them. The following 
information needs have been identified with this function: 

P.9. A New Developments in Threat Technology 

(Instruments/Methods) 

P.9.B New Technological Vulnerabilities in National 

Resource Systems 

P.9.C State-of-the-Art Security Technology for Dealing 

with Threats/Vulnerabilities/ Consequences 
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PEMA muse keep ebreesc of new trends and developments that are 
likely to change the vulnerabilities of the various national 
resource systems. For example, as transportation systems 
become more dependent on electronic data processing for such 
functions as scheduling, routing, maintenance, and coordina** 
tion, their computers become increasingly vulnerable targets. 

4.2.10 Liaison with Civil Security Community (P.IO) 

The Civil Seciirity Division is primarily a recipient and 
end'-user of information supplied by other agencies and organi- 
zations in the civil security community. Its success is there- 
fore largely dependent on developing and maintaining good 
relationships and effective liaison with other elements of this 
comomnity. The following information needs serve this purpose: 

P.IO.A POC Lists of Reciprocal Liaison Counterparts, by 
Agency and Subject Area 

P.IO.B Updated Reference Material on Organizational 
Structure and Roles of Other Civil Security 
Elements 

P.IO.C Checklists/Briefs of Current Topics, Problems, 
Concerns of Mutual Interests 

4.2.11 Represent FEMA on Interagency Civil Security 
Committees/Groups/Task Forces (P.ll) 

To enable the various agencies with civil security interests to 
discuss issues and problems and share viewpoints, many inter- 
agency committees, groups, and task forces have been or will be 
established. The FEMA Civil Security Division has a vital 
interest in being represented in these organizations, or at 
least being aware of their activities. As the following 
information requirements indicate, this representation requires 
knowledge of the agenda of each group, of FEMA's own position 
on various issues, and of the positions and viewpoints of other 
agencies: 
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P.Il.A Master List of laterageaey Groups concerned with 
Civil Security matters 

P.Il.B Agenda of Key Issues/Problems to be Addressed 

P.ll.C Participating Agencies, Structure of Committee, 

Members of Delegations 

P.ll.D Terms of Reference on FEMA Position to be 
Advocated, and Strategy 

P.ll.E Other Agencies' Positions and Views 

P.ll.F Cumulative Record of Proceedings (Proposals, 

Agreements, Impasses, etc.) 

P.ll.G Formal Products/Outcomes Resulting from 

Committee Action (Final or Incremental Findings/ 
Reports) 

4.2.12 Training/Test/Exercise/Caming Support (P.12) 

For the FEMA Civil Security Division to support training, 
tests, exercises, and games related to civil security, it must 
have information on the following five subjects: 

P.12. A Sponsor and Participants 

P.12.B Planned Goals and Objectives 

P.12.C Schedules/Tifflc Frames 

F.12.0 Postulated Scenario/ Syllabus to b« Followed 

P.12.E Control Itechanism Employed 

The control mechanism refers to the management of exercises, 
for example, the operational constraints and degrees of freedom 
in running them, and the method of determining success or 
failure. 
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4.2»13 Periodic Strategic Nat Appraisals of Civil Security 
(P.I3) 

A vital function and output product of the Civil Security 
Oiviaion ia the appraisal of the Ration's civil security 
posture. This entails keeping abreast of the current threat 
climate, recent civil security incidents and their conse- 
quences, major shortcomings in civil security, and remedies 
underway to redress those shortcomings. The current civil 
security capabilities of Federal, State, and local governments, 
and the private sector must also be evaluated frequently, not 
only to ensure an adequate defensive posture and response 
mechanism but also to ensure that appropriate steps are being 
taken to mitigate and ameliorate adverse consequences. The 
list below reflects the information needed to satisfy this 
function: 


P.13.A Historical/Statistical Data on Changing- 

Character, Patterns, Trends in Threat Climate 
(Domestic and Foreign) 

P.13.B Historical/Statistical Data on Nature, 

Frequency, Distribution, Consequences of Recent 
Civil Security Incidents Against National 
Resource Systems 

P.13.C Major Civil Security Problem Areas/Shortcomings 
Experienced (Mitigation, Preparedness, Response, 
Recovery) 

P.13.D Status of Remedial Measures Underway 

P.13.E Federal, State, Local and Private Sector Civil 
Security Capabilities and Readiness to Mitigate 
and Ameliorate Adverse Consequences 
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4.3 Trans-event Information Needs 

Identified in this section ere the information categories 
required to fulfill the essential civil security functions 
during the trans^event response period. 

4.3.1 Verification of Ocetirrence (T.l) 

When the Civil Security Division receives notification of a 
civil security event, activities are immediately initiated to 
provide verification of occurrence. The following three items 
of information are essential to this function: 

T.l. A Report(s) of event (What, Where, When, How 

Serious) 

T.l.B POC Roster for Verification/Corroboration/ 

Amplification 

T.l.C News Media Bulletins/Accounts 

The point-of'-contact roster contains names of Federal, Stats, 
local, or private sector response-reaction principals whose 
timely input can provide an accurate assessment of the 
unfolding events. 

4.3.2 Warning and Alerting Notification (T.2) 

Once a civil security eveat has occurred and been verified, Che 
Civil Security Division must ensure that priority need-to-know 
agencies, direction and control centers, and key personnel are 
notified in an orderly manner with minimal delay. This noti- 
fication might actually be performed by the OEO/EICC. The 
following three information items ake needed to fulfill this 
function: 


T.2. A Priority Need-to-Know Agencies/Centers/Key 

Personnel 
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T.2.B Roster of POCs 

T.2.C Checklist Notification Procedures 

4,3»3 Decision Support (T.3) 

During a civil security event, FIHA must provide timely esti- 
aietas end esseesments of the unfolding events to permit the key 
decision mekars to make wise end effective decisions aimed at 
minimizing potentiel damage or eawlioreting negative conse- 
quences. The civil security staff, depending on its degree of 
involvement, must therefore be prepared to acquire — or assist 
the OEO/EICC in acquiring — the following types of needed 
decision-support information: 


1.3 .A Direct Impact Damage/Disruption Incurred (Locus, 

Type, Systems Affected, Scale) 

T.3.B Pertinent Pre-calculated Implications/Potential 

Consequences Extrapolation Data 

T.3.C Status Updates on Situation/ Changes 

T.3.D Status Updates on Operational Response-Reaction 

Measures 


T.3.E 


T.3.P 


T.3. 6 


T.3.H 


T.3. 1 


. T.3.J 


.Relevant Policies, Doctrine, and Strategy 
Alternatives 

Matrix of Responsibility/ Jurisdiction (Federal, 
State, Local, Private Sector) 

Readiness Posture/Capabilities of Response 
Elements Apt to be Involved 

Cuaulacive Requests for Assistance (Source, 
Status, Disposition) 

Agency Estimates of Likely Additional 
Requirements 

Resource Availability Data 
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T.3.K Views, Needs, Problems of Affected 
Agencies/Interested Parties 

T.3.L Emergency Operations Procedures of Emergency 
Information and Coordination Center/Office of 
Emergency Operations 

4.3.4 Decision Implementation Action (T.4) 

The information required for implesienting the decisions 
dictates that the FEMA Civil Security Division have at its 
disposal a master list of agencies having primary, coordinate, 
and support responsibilities and of the procedures for issuing 
requests and instructions for each agency. The Division will 
also need periodic updates of each agency's responsibilities 
and points-of-contact. Thus the following types of information 
are required: 

T.4. A Master List of Agencies Having Primary/ 

Coordinate/Support Responsibilities 

T.4.B Procedures for Issuing FEMA Tasking/Requests 

T.4.C POCs in Affected Agencies 

4.3.5 Interim Coordination of Immediate Emergency Actions (T.5) 

As noted in Chapter 3, the civil security staff may temporarily 
have to coordinate, or assist OEO/EICC in coordinating, the 
Federal response at the outset of a major civil security 
event. The Division staff therefore has to be familiar with 
the primary points-of-contact in each agency and know the 
agency-specific procedures for orchestrating coordination. The 
conduct of this interim coordination function will require the 
following information: ^ 

T.5. A Emergency Action POC Roster and Procedure 
Checklist 

T.5.B Existing Applicable Plans 
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T.5.C Operative Direction and Control Infrastructure 

T.5.D Available Rescue/Evacuation Lift Aaseta 

T.5.E Candidate Host Area/Safe Haven Relocation Sites 
(Shelter and Logistic Support Capacity) 

T.5.7 Available Damage Control/ Containaunt Resources 

T.5.6 Available Protective Equipment » Supplies, 

Personnel 

T.5.H Status of Priority Actions in Outside Agencies 
(Unilateral and Collaborative) 

The status of priority actions by outside agencies is monitored 
to ensure prompt attention to activities deemed most critical. 

4,3.6 Initiate Execution Planning/ Asset Mobilization/ 

Readiness for Recovery (T.6) 

During the trans-event response period, it may be necessary to 
initiate steps as early as possible for handling the needed 
recovery and stabilization measures. In preparing for this 
transition to the post-event recovery period, the Civil 
Security Division will require information on the following 
topics: 

T.6. A Master List of Agencies Having Recovery 

Responsibilities 

T.6.B Existing Recovery Agencies 

T.6.C POCs within Recovery Agencies 

T.6.D Readiness and Execution Procedures (Federal, 

State, Local, Private Sector) 

T.6.E Recovery Resource Requirements Estimates 

T.6.F Resource Location/ Availability 
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4.3.7 Congressional and Public Affairs Update (T.7) 

The Civil Security Division must be in a position to provide 
accurate, timely, and appropriate civil security-*related infor- 
mation for dissemination through the public affairs and Con- 
gressional relations' staff of FEMA. This requires access to 
up-to-date information on the civil security activities of all 
agencies involved in the event. The internal FEMA procedures 
for preparing and briefing these staffs must be well understood 
by civil security program personnel. 

T.7. A Accurate, Current Data on Event and Response 

T.7.B Procedures/ Criteria for Briefing/Updating FEMA 
Congressional Relations/Public Affairs Staffs 

4.3.8 Hand-off and Transition to FEMA Response Management 
Principals (T.Sf 

As the trans-event response phase comes to an end, the Civil 
Security Division personnel need to prepare for the transfer of 
responsibilities to the FEMA response management principals. 

As noted before, such a transfer may occur earlier in the 
trans-event phase. Two information needs must be satisfied to 
achieve this transition: 

T.8.A Matrix of Responsibilities within FEMA 

T.8.B Record of FEMA Actions Completed, in Process, 

and Pending 

Accurate records of the FEMA actions completed, in process, or 
pending are required to avoid duplication of effort and to 
expedite recovery measures. 

4.4 Post-event Information Seeds 

This section identifies the information categories required to 
fulfill the essential civil security functions during the 
post-event recovery period. 
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4.4.1 Aaaist FEMA Emergency lafonaation and Coordination 
Cynter/Offic# of Emcrgeacy Operations and Staff 
Elenentt (R.l) 

During the poet**eveat recovery period, Civil Security Division 
staff elements and resources must remain available to assist 
the Office of Emergency Operations, the Emergency Information 
and Coordination Center, and other FEMA staff members in 
addressing residual civil security concerns, recognizing poten** 
tlal civil security contingencies, and maintaining contacts 
within the civil security community involved or interested in 
the recovery phase. The list below covers the information 
required to perform this function: 

R.1.A Checklist of Potential Civil Security 
Contingencies During Recovery 

R.I.B Residual Civil Security Concerns of Agencies 
Involved in Aftermath of Event 

R.l.C POC Roster of Civil Security Community Involved/ 
Interested in Recovery Phase 

4.4.2 Assess Continuing/Follow-on Civil Security Threat (R.2) 
During the post^event recovery period, the Civil Security 
Division must recognize that additional targets and national 
resource systems might be threatened. Forecasts and risk 
analyses, combined with updated threat information, may be 
needed to cover these possibilities. This threat assessment 
activity requires the following information: 

R.2. A Updated Threat Information 

R.2.B Additional Possible Targets and Other National 

Resource Systems that Might be Affected 

R.2.C Projected Risk Analysis Estimates 
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R.2«0 POC Roster for Threat/Risk Forecasts 

R*2.E POC Roster of Parties to be Advised 

4.4.3 Monitor Recovery Phase Activities/Progress (R»3) 

Civil security personnel should monitor recovery phase activi- 
ties and develop an overview of recovery operations to ensure 
that civil security concerns are being fully addressed. They 
should review And » when necessary, change FEMA's criteria and 
procedures for reporting to interested agencies. And they 
should update their point-of-contact rosters to reflect neces- 
sary changes in the communication network. This will require 
information on the following four topics: 

R.3.A Summary Overview of Recovery Operations 

R.3.B Sta.tus of Current and Planned Civil Security 
Related Actions 

R.3.C Criteria/Procedures for Reporting to Interested 
Agencies 

R.3.D POC Roster of Agencies Needing Civil Security 
Update 

4.4.4 Develop After-Action Lessons Learned (R.4) 

To assess the effectiveness of plans and programs, as well as 
overall national policy on civil security issues, it will be 
necessary for all agencies involved in the event to provide 
after-action reports to the FEMA Civil Security Division. 

These reports should include an assessment of successes, 
failures, and problems, accompanied by a critique of agency 
actions and suggested future improvements. FEMA civil security 
personnel will analyze these and their own after-action reports 
and prepare a suxomary document outlining the lessons learned 
and the needed remedial actions. The information requirements 
noted below are aimed at the fulfillment of this function: 
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R.4.A RACOQStructioa of Pre-Event Civil Security 
Posture 

R.4.B Cufflulstive Archival Journal/ Chronology of -Event, 
Response, Recovery Experience 

R.4.C Detailed Documentation of Salient Problems 
Encountered 

R.4.D Logs, Records, and Observations on System 
Performance (Achievements and Deficiencies) 

R.4.E Critique Reviews/ Suggest ions by Participants 

4.4.5 Reappraise/Adjust Policy. Plans. Programs (R.5) 

Section 4.4.4 mentioned the Civil Security Division’s need to 
develop after-action lessons learned from a civil security 
event to adjust future policy, plans, and programs. This 
activity provides a feedback mechanism for improving aiitigation 
and preparedness plans and programs, as well as future 
trans-event response and post-event recovery operations. Based 
on careful evaluation of the effectiveness and appropriateness 
of the policy, plans, and programs, as revealed by the after 
action reports on the recently managed eaiergency event, the 
Civil Security Division will initiate, coordinate, and ensure 
that important remedial adjustments are made internally within 
FEMA and by the other appropriate Federal agencies. The imple- 
mentation of such adjustments requires the following 
information: 

R.5. A Policy Issues Bearing on Civil Security Elevealcd 

by Emergency 

R.5.B Appropriateness and Adequacy of Civil Security 
Plans to Cope with Event 
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R.5.C Civil Security Program Shortfalls Demonstrated 

R.5.D Indicated Areas of Civil Security Information 
System Support Needing Improvement 
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5. INFORMATIOM PARAMETERS AND COHSTRAINTS 

In the previous chapter, the types of Information required to 
support the respective civil security functions were identified 
and discussed* The next step is the development of a more 
detailed characterization of the operational parameters and 
constraints associated with the t3rpes of information identified* 

5*1 Attributes of Civil Security Information Requirements 
The following attributes establish the framework for refining 
the character of the civil security information requirements: 
source of information, security classification, frequency, 
accessibility, and application. 

5*1*1 Source 

FEMA will have to task many different sources to ensure that 
the information needed to meet civil security functions is both 
available and complete* Other agencies have statutory respon’* 
sibility for developing and implementing civil security plans 
and programs, for managing the response during an act;:al event, 
and for ensuring that appropriate security steps are taken. 
However, in its oversight and focal point roles, FEMA must 
recognize that the primary action agency may not be the 
singular supplier of civil security information* Additionally, 
Civil Security Division personnel must be able to synthesize 
the information from all sources to provide the most useful 
product for internal and external consumers* It should be 
noted that some sources will provide information only in 
support of pre*^vent preparedness activities* Other sources 
will be brought into play only during trans^event response or 
post-event recovery periods, depending on the nature of the 
event as it unfolds* 
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5.1.2 Security Claasificatioa 

Th« security classificatioa of civil security information can 
be expected to run the gamut from unclassified to top secret 
and, at times, will require various compartmentalized or code 
word intelligence clearances. The level of security classifi** 
cation will depend on the source, the specific content of the 
data, the sensitivity attached to it, and individual scena- 
rios. Civil security and other FEMA personnel must constantly 
be aware of the potential need to reclassify the information 
that they produce as a result of data aggregation. 

5.1.3 Frequency 

The frequency with which civil security information is needed 
and the frequency with which this information requires updating 
will obviously vary in terms of the functions to be performed, 
the time being considered, and the urgency of operational 
requirements. In general, those functions that pertain to 
pre-event mitigation and preparedness measures will permit a 
more routinized flow of information, longer intervals between 
updates, and less urgency in securing new or updated data. In 
such cases, the entire process is likely to be fairly predict- 
able, regularized, and controllable. During the occurrence of 
actual terrorist, civil disorder, sabotage, or subversion inci- 
dents, however, the information collection, interpretation, and 
dissemination processes are likely to change dramatically. In 
such trans-event periods, the frequency of need and frequency 
of update become dependent on situational imperatives that are 
inherently unpredictable. Thus the need for information and 
the update frequency are likely to be more dynamic— varying 
with the nature, scope, and pace of the individual event as it 
unfolds. 
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5.1.4 Acceasibility 

FEMA's access to civil security information may take three dif*' 
ferent forms: (1) routine; (2) limited; and (3) ad hoc 

requests. Routine information is received on a repetitive, 
regular, or periodic schedule from numerous governmental and 
private sector sources, and it is based on pre-established 
mutual understandings and procedures. Limited access refers to 
information that may be similarly programmed in advance, but 
which can only be obtained or received, under stipulated condi- 
tions, depending on the nature of the particular event and the 
security classification of the information. Ad hoc requests 
refer to information that is obtained by FEMA on a case-by-case 
basis, that is, only when such information is expressly 
requested and the supplier agency agrees to respond. 

5.1.5 Application 

In a general sense, civil security information is utilized in 
two ways. First, some types of information are necessary to 
support internal civil security functions. Second, Civil 
Security Division personnel, after the receipt of information, 
will analyze, synthesize, and condense it. Output products may 
then be generated and sent to other FEMA elements or to 
agencies and organizations external to FEMA. 

In the following sections of this chapter, each category of 
information required for a particular function is discussed 
within the context of these information attributes. Section 
5.2 presents the parameters and constraints of information 
requirements to support pre-event preparedness functions. 
Section 5.3 presents a discussion of the parameters and con- 
straints relating to information on trans-^vent response func- 
tions; and Section 5.4 deals «rith post-event recovery functions. 
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5*2 Pre-Event Phase - laforniacioa to Suataia Preparedneaa 
Activities 

Section 2.3 notes that the audiences with wnom FEMA must com- 
nunieate in carrying out its mission are mxmerous and diverse. 
This statesMnt is particularly true regarding civil security 
functional information requirements. The information to 
support preparedness functions forms the baseline for the 
communication process which is essential in carrying out civil 
sec\irity planning, oversight, liaison, and training activi- 
ties. The following sub-sections present a discussion of the 
parameters and constraints relating to pre-event information 
needs. Further details on these parameters and constraints are 
presented in tables at the end of each subsection. 

5.2.1 Tasking the Providers of Threat Assessments (P.l) 

FEMA will have to loolc to the intelligence and law enforcement 
agencies as points-rot-contact as well as to private security 
organizations. The FEMA Civil Security Division requires 
standard procedures for gaining access to tne various data 
bases on a daily basis. FEMA's authority to tasic other 
agencies for this purpose will necessarily also provide for 
access to the various bodies of classified data. FOC rosters 
will probably be used on a daily basis to maintain contact with 
agencies. Any changes in FOCs should be transmitted to FEMA on 
a weekly basis. 

5.2.2 Synthesis of Available Threat Assessment Froducts (F.2) 
As can be seen in Table F.2, the primary sources of threat 
assessment products will be the agencies with intelligence and 
security missions as well as those with responsibilities for 
emergency management of the national resource systems. Supple- 
mental data can also be provided by tne private sector througn 
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corporation security offices, the media, and the law enforce** 
ment arms of the State and local governments. In those 
instances where the security classification includes compart- 
mentalized or code word intelligence, special arrangements will 
have to be made to ensure that FEMA civil security personnel 
have access to the essential threat assessment data. The Civil 
Security Division will synthesize these data and disseminate 
the information to the necessary recipients. Strategic-type 
studies should be reviewed by FEMA on a monthly basis. Weekly 
updates of recent activities and changes in forecasts will 
ensure currency of strategic threat information. 

5.2.3 Risk Analysis (P.3) 

The intelligence and law enforcement community will be the 
providers of information needed for civil security risk 
analysis activities* The nature of the data, the sensitivity 
associated with collection processes, and the potential value 
to hostile interests will place most information at the upper 
levels of security classification. The civil security staff 
should review risk analysis data on a regular basis. Monthly 
updates should ensure adequate currency. The classification 
level will necessitate restrictions or limitations on FEMA's 
access to risk assessment data maintained by other agencies. 

The finished products of risk analysis obviously have both 
internal and external application. 

5.2.4 Policy Development (P.4) 

Information will be provided by the various agencies and 
organizatipns involved in responding to policy and other regu- 
latory issuances. Most information will be unclassified, but 
mod's and some of the views of cognizant or affected agencies 
may fall into the classified arenas. Frequency of use and 
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update requirements ere not predictable and will depend upon 
the priorities of eech administration. FEMA should have no 
restrictions or limitations on access to required informa- 
tion. FEMA will produce a consolidation of the views of the 
major parties concerned and offer a susnation of the policy 
implementation requirements for external use. 

5.2.5 Plsnning Guidance (P.5) 

FEMA will look to a variety of sources in providing civil 
security planning guidance to the executive agencies. The 
sources can be expected to range from Federal, State, and local 
governments to various public interest groups (National Gover- 
nor's Association, Council of State Governments, National Asso- 
ciation of Counties, National League of Cities, U.S. Conference 
of Mayors, etc.), and other private sector organizations. In 
most eases policy information will be unclassified. But infor- 
mation on threats and documents outlining detailed plans and 
giving the capabilities, limitations, and needed resources of 
agencies are likely to carry various levels of secturity classi- 
fication. Since the Civil Security Division must be contin- 
ually aware of national policy posture in all its activities, 
frequency of need and update is on-going rather than periodic. 
Some data, e.g., those on threat and vulnerability, are suffi- 
ciently dynamic to require review and updating at least 
monthly. The information required for planning guidance should 
be routinely accessible to authorized FEMA civil security 
personnel. 

5.2.6 Plana Review and Evaluation (P.6 ) 

As reviewers and evaluators of plans, civil security program 
personnel must have access to the civil security plana of 
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Federal, State, and local agencies. The security classifica-- 
tion of information on plans will depend on the agency, its 
responsibilities, and the nature of postulated scenarios. 
Updating of points^f**contact should occur at least monthly, 
and updating of plans as required. FEMA personnel should have 
routine access to most civil security plans. It may be neces-- 
sary to make ad hoc requests for certain sensitive plans, as 
well as for status reports when new plans or significant modi- 
fications are mandated, e.g., when there are changes in the 
regulatory base or changes in threat assessments. 

5.2.7 Program Coordination (P.7) 

As in the case of program guidance and plan review and evalua- 
tion, information will be needed from all the Federal, State, 
and local agencies that have responsibility for, cognizance of, 
or are affected by civil security actions. This information 
will generally fall in the unclassified to secret range, with 
some in compartmented levels. Access to information on program 
coordination should generally be routine. Some limitations or 
restrictions may be imposed when compartmented information is 
required. Most of the information will be used by FEMA person- 
nel on an internal basis. Such items as the comprehensive 
catalog of programs and a master roster of program managers 
should be made available to the various agency program man- 
agers. A basic catalog of mitigation and preparedness techni- 
ques and technology should be produced and distributed, as 
required. Finally, status reports will he provided to FEMA 
senior management, and be used for the formulation of the 
periodic Director's report to the President. 

5.2.8 Initiate Proposed HSC/Legislative Action (P.8) 

The need to seek National Security Council (NSC) or legislative 

assistance in resolving problems will require information on 
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the opinions and views of the affected agencies, as well as 
internal staff views of interested FEMA elements. Depending on 
the nature of the problem and Che agencies involved, the infor- 
mation may require security classification. The priorities of 
the administration will determine Che frequency with which FEMA 
requires the information to support this functional area. 

While some of Che information may be obtained via other pro- 
grammatic activities, it is anticipated chat imich of the infor- 
mation will be requested by FEMA on an ad hoc basis. FEMA will 
analyze the available data, summarize the nature of Che pro- 
blem, and recommend a proposed course of action Co be submitted 
Co Che MSC or appropriate legislative offices. 

5.2.9 Advisory Assistance (P.9) 

The primary sources will be those agencies that furnish intel- 
ligence and security (e.g. law enforcement) information. Much 
of this information will be highly classified. Frequency of 
need will be dependent on Che release of new developments in 
technology, the responsiveness of the security community in 
developing countermeasures, and the ability of Che intelligence 
community to maintain currency on the activities of adversary 
groups. The Civil Security Division will provide reports on 
new threats and security technologies to authorized 
organizations . 

5.2.10 Liaison with Civil Security Community (P.IO) 

The FEMA civil security program will require that information 
on poinCs-of-contact, organizational structiires, current 
topics, problems, and issues be furnished by each of the 
cognizant agencies. Most information will be at the unclassi- 
fied and confidential levels. Since information will be used 
frequently, it should be updated often enough to ensure 
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currency, particularly with respect to changes in points-of- 
contact. FEMA should require and expect fairly routine access, 
with some limitations imposed in the areas of agency-spqcific 
or unique civil security concerns. Information utilized by 
FEMA civil security personnel should generally be made 

e 

available to other agencies in the civil security community. 

3.2.11 Represent FEMA on Interagency Civil Security 
Committees/Groups/Task Forces dP.ll) 

The Civil Secxirity Division will require input from within FEMA 
concerning the FEMA position on a variety of topics. Informa-* 
tion from other agencies that participate in interagency meet- 
ings will be required to ensure that the FEMA position is con- 
ceptually correct and current. The security classification 
will generally be at the secret level. Since most groups can 
be expected to meet on a monthly basis, the Civil Security 
Division should review and update its data monthly. Any 
products, i.e., reports, studies, and meeting minutes, may be 
transmitted to other FEMA staff elements on a selective basis. 
Accessibility to outside agencies will probably be constrained 
in such areas as agency internal positions and viewpoints. 

5.2.12 Training. Test, Exercise, and Gaming Support 
(Civil iacurify-Ralated ^paets) (P.12) 

The Civil Security Division will require information from the 

sponsor of these activities, from participating agencies, and 

from other involved FEMA elements. These same sources will be 

tasked to provide the Division with relevant data on test 

goals, schedules, scenarios, etc. The Division will evaluate 

the pertinence and applicability of the civil security aspects 

and provide pre-test feedback to concerned players. Some 

information, such as goals, objectives, and scenarios, will 

fall into the confidential and secret classification levels. 
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Ttie need for infonsacion will depend on Che ciming of planned 
training. Updates and the civil security aspects of tests will 
be required daily during the execution of tests. Access will 
generally be on a routine basis with some limitations imposed 
on test scenarios because of cneir security classification.* 

The Civil Security Divison will generate civil security goals 
and objectives for inclusion in test scenarios. 

5.2.13 Periodic Strategic Set Appraisals of Civil 
Security (P.13) 

The sources available to FEMA in developing consolidated net 
appraisals include internal FEMA elements > cognizant agencies, 
the Hational Security Council, and tne relevant intelligence 
and security communities. A substantial portion of the infor- 
mation will be dealing with the threat climate, including civil 
security problem areas and shortcomings. The security classi- 
fication can therefore be expected to extend into compartmented 
intelligence levels, with commensurate access restrictions. 

The Civil Security Divison should review appraisals monthly. 
Problems and shortcomings should be forwarded from tne affected 
agencies as tney are discussed. Remedial measure status 
reports, prepared on a weekly basis, will ensure that the 
Division is able to maintain currency. Information concerning 
civil security problems, remedial measures status, and organi- 
zational civil security capabilities will be documented and 
distributed to authorized civil security community personnel. 

5.3 Trans-Event Phase - Information for Response Management 
Depending on the amount of warning received prior to an event 
and the nature and scope of the event, the Civil Security Divi- 
sion may either play a significant initial role in event 
response or merely act as an advisor on the civil security 
aspects of an event. The information needed during this 
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phase — in terms of frequency of use and updating, classifica- 
tion, and source— will vary dramatically based on the event 
scenario. As a result, the Civil Security Division must ensure 
that the information processes are in place to support the easy 
flow of information under varying conditions. The need for an 
information system that can accomodate a variety of demands and 
yet be flexible enough to ensure comprehensive access to a 
broad spectrum of information is underscored in the following 
discussion of the detailed parameters and constraints asso- 
ciated with response management information requirements. 

5.3.1 Verification of Occurrence (T.l) 

The primary sources of information for an impending event or an 
event-in-progress will usually be the agencies with tactical 
indications and warning centers. The nature of the event, the 
target, and the type of perpetrator will determine the security 
classification. For example, information regarding an impend- 
ing massive demonstration with a potential for large-scale dis- 
ruption, will probably be unclassified; but a threat of assas- 
sination against the President or other elected officials would 
be handled through classified channels of communication. 
Regardless of classification, information about impending or 
actual events that impact the civil security program should be 
routinely made available to the Civil Security Division. Where 
the Division is the first activity notified within FEMA, it 
will transmit the notification to the other relevant FEMA ele- 
ments. FOG rosters will be consulted frequently during the 
event as it unfolds, so the rosters will be current. They 
should be updated at least daily, preferably with immediate 
notification of changes in key personnel. Depending on the 
nature of the event, the radio, TV, and the wire services may 
be in the. best position to provide inmediate information on the 
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occurrence of an event. A periodic summary of news media 
information should be sent to FEMA emergency response manage- 
ment elements by the Civil Security Division. 

5.3.2 Warning and Alerting Notification (T.2) 

Each agency should provide FEMA with information on its key 
personnel. During an event* the points-of-contact roster 
should be checked at least daily to ensure currency. To make 
sure that all affected agencies can be contacted by FEMA per- 

s 

sonnel, each agency should inform FEMA of any unique notifica- 
tion procedures. Because of* the classification level of key 
personnel and POC rosters* procedures within some agencies may 
be classified. Thus FEMA may have to conform to certain 
restrictions or limitations on access. The information will be 
used internally Co make certain that the affected agencies can 
be notified of an event by FEMA on a timely basis. 

5.3.3 Decision Support (T.3) 

Sources with direct and tangential responsibility must be in a 
position to support FEMA's civil security activities in the 
response period. For example, there is an obvious interdepen- 
dence between information concerning the damage and disruption 
incurred and the potential consequences. Depending on the 
nature of the event scenario* the information classifications 
will range from unclassified through at least secret levels. 
Information required by civil security will be accessed 
frequently. It should be updated at least hourly in the early 
stages of the event. The scenario will ultimately determine 
the need and frequency of update. Current emergency procedures 
that define the Civil Security Division-Emergency Information 
and Coordination Center interface should be in place and 
reviewed at least monthly by the civil sectirity staff. They 
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snould also be updated moathly. The rapidity vita vnich the 
event unfolds will probably dictate the need for ad hoc 
requests in the early stages of the event. Because the infor- 
mation may be highly classified, some access limitations can be 
anticipated. The Civil Security Division will also be required 
to provide decision makers with consolidated information on the 
civil security resources required during and iomediataly 
following the actual event. 

5.3.4 Decision Implementation Action (T.4) 

The Civil Security Division will require information on 
specific delegations of responsibility within each affected 
agency. Information on tasking procedures should be provided 
by other FEMA. elements. The event scenario will determine fre- 
quency of need. The Division will also need periodic updates 
of each agency's responsibilities and points-of-contact. Most 
information to support FEHA's functions in this area should be 
available on a routine access basis because it will be 
unclassified. 

5.3.5 Interim Coordination of Immediate Emergency Actions (T.5) 
During the trans-event phase, the Civil Security Division must 
have information on the primary civil security points-of- 
contact from each agency. It will frequently refer to informa- 
tion on rescue and evacuation assets, resources for damage 
control and containment, and the status of emergency actions to 
date. The frequency of updates will be dictated by the nature 
of the scenario. The Division staff should have ready access, 
although access to soma information will be limited by high- 
level security classification. The Division, in collaboration 
with OEO, will prepare up-to-date summaries of information on 
the civil securityrelated aspects of response operations, such 
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aa ralocacion sices, special proceccive equipoenc, supplies, 
and skilled personnel, co Che affecced agencies. 

5.3.6 IniciaCe ExecuCion Planning. AsseC Mobilizacion, and 
Readiness for Baeovery (T.6j 

Agencies Chat are responsible for recovery accivicies should 
provide Che Civil Securicy Division wich relevanc informacion 
on plans, procedures, and resources for posC->evenC recovery. 
While mosc of Che informacion should have been provided as pare 
of preparedness accivicies, Che nacure and scope of Che evenc 
requires chac agencies* give Che Division necessary updaces and 
changes. MosC of cne informacion snould be roucinely available 
Co FEMA, alchough Che securicy class if icacion oiay diccace some 
rescriccions. As informacion on recovery requiremencs and 
resource locacion is compiled, ic should be cransmicced Co Che 
affecced agencies. 

5.3.7 Congressional and Public Affairs Opdaces (T.7) 

The Civil Securicy Division muse nave access co up~co->daCe 
informacion on cne civil securicy accivicies of all agencies 
involved in Che evenc. The incernal FEMA procedures for 
preparing and briefing informacion for cne FEMA Congressional 
relacions and public affairs s Caffs will be used frequencly 
during Che evenc. Classified daca on currenC evencs may have 
CO be accessed and CransmiCCed Co Che Congressional. 


5.3.8 Hand-off/Transicion Co FEMA Sacovery Managemenc 
Principals (T.8 ) 

Ttte Office of Emergency Operacions should inform Che Civil 
Securicy Division of Chose FEMA elemenCs chac will ulcimacely 
assume response managemenc. In Cum Che Division will provide 
Che EICC/OEO wich a record of ics accions during ics inicial 
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period of event management* It will also provide hourly 
updates of its activities related to event response. Informa- 
tion on responsibilities will likely be unclassified and rou- 
tinely available to the Division. Notification of changes 
should be furnished to the Division as frequently as necessary. 

3.4 Post-Event Phase - Information Associated with Recovery 
In the recovery phase, the Civil Security Division has two 
generic information tasks: (a) addressing civil security- 

related issues associated with the event or with the recovery 
operations, and (b) evaluating the overall effect ivenesss of 
the Federal, State, local and private sector civil security 
activities during the emergency. As noted in Chapter 4, the 
information required to support recovery activities involves 
maintaining communication with all agencies that were partici- 
pants in the event and documentation of their actions. The 
specific items and sources of information will vary, depending 
on the nature of the event* The parameters and .constraints 
discussed in this section continue to underscore the need for 
data gathering and information dissemination that is suffi- 
ciently flexibile to allow for varied sources, classification, 
and frequency of use. 

5.4.1 Assist PEHA Emergency Information and Coordination 
Center/Office of Emergency Operations and Staff 
Elements (R.l) 

Information on possible civil security probleais arising from or 
impinging upon recovery must be acquired from the agencies 
affected and conveyed to all interested parties. Most of the 
information collected and transmitted during this phase will 
have a m a ximum security classification of secret and should be 
accessible on a routine basis. Information on potential new 


5-38 


Declassified in Part - Sanitized Copy Approved for Release 2011/12/09 : CIA-RDP89B01330R000600870001-6 



siNaini tnta qnt oio/gaii xsissr - i*« mri 


Declassified in Part - Sanitized Copy Approved for Release 201 1/12/09 : CIA-RDP89B01330R000600870001-6 



























Declassified in Part - Sanitized Copy Approved for Release 2011/12/09 : CIA-RDP89B01330R00060087000i-6 


eontingeaeies and reaidual on concerns cnist be available on at 
least a daily basis. When there is a significant potential for 
secondary or tertiary effects (which may alter the scale or 
character of recovery demands), the Civil Security Oivison 
should receive and disseminate information on civil security 
concerns to the EICC/OEO elements on a daily basis, or more 
frequently if circuxastances warrant. 

3.4.2 Assess Continuing/Pollow^n Civil Sectirity Threat (R.2) 
Assessment information on additional targets and resource 
system flust be furnished by the intelligence and security 
communities. They should also furnish threat information and 
estimates updates. To ensure that the Civil Security Division 
can maintain flexibility and be prepared to modify its civil 
sec\irity operations and network of communication channels, POC 
rosters must be updated daily. Information for these activi- 
ties will cover the entire range of security classification. 
Reports on civil security threats must be disseminated to 
affected members of the intelligence and security community. 

5.4.3 Monitor Recovery Phase Activities/Progress (R.3) 

Civil security personnel should monitor recovery phase activi- 
ties based on informacion from all agencies involved. FEMA 
should provide procedures for reporting to interested agen- 
cies. Agency point-of-contact rosters should be provided to 
the Civil Security Division, and updates should be forwarded 
daily. Since most of the information on this subject will be 
classified secret or below, access by FEMA should be on a 
routine basis. 

5.4.4 Develop After-Action Lessons Learned (R.4) 

All agencies involved in the event should prepare after-action 

reports for the FEMA Civil Security Division. During the 
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recovery period, Che Division will need such hiscoricel infor-' 
tnecion on a daily basis as it consolidates and summarizes the 
record of what transpired. Agencies should furnished updates 
whenever there are significant ohanges in their activities. 

Much of this information will be security sensitive and will 

e 

require appropriate classification and commensurate resCric-> 
cions on access. Copies of these summaries, including appro*- 
priate recommendations, should be disseminated to all appro- 
priate agencies and organizations in the civil security 
community. 

5.4.5 Reappraise/Adiust Policy. Plans, and Progr«"«« (R.3) 

All agencies involved in the event must provide the Civil 
Security Division with after action reports on the event. As 
in the case of after-action reports, much of the information on 
needed adjustments and improvements in civil security policy, 
plans, and programs will be security sensitive and will there- 
fore require appropriate classification and restriction on 
access. Recommendations on improvements needed will be for- 
warded to affected agencies. 
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CIA Central Intelligence Agency 

Choke Points Functional/ logistic areas of highest 

vulnerability within a national resource 
sy s tea 


Civil Security Mitigation, preparedness, response, and 

recovery activities to reduce the 
consequences of terrorism, civil disorder, 
sabotage, and subversion 

Civil Security Division Division under the Office of Mobilization 

Preparedness within the National 
Preparedness Programs Directorate of FEMA 
concerned with civil security matters 


Code Word 


Compartmented 


A specific security classification above 
Top Secret 

A specific security classification above 
Top Secret 


Control Mechanism In an exercise, test, or game, the method 

by which it is managed, the operational 
constraints and degrees of freedom, and the 
method f or . de termining success or failure 

Critical Nodes Functional/ logistic areas of highest 

vulnerability within a national resource 
system 


CS 


•Civil Security 


CSD 

DEA 

DIA 

DOC 

DOE 

DOJ 

DOT 


Civil Security Division of FEMA 
Drug Enforcement Administration 
Defense Intelligence Agency 
Department of Commerce 
Department of Energy 
Department of Justice 
Department of Transportation 
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Essential element(s) of information 


EICC 


Emergency Information and Coordination 
Center within FEMA 


Executive order 


Executive Office of the President 
Federal Bureau of Investigation 
Federal Communications Comaission 


mui 


FEMA Regions 


Federal Emergency Management Agency 

The ten geographic regions of FEMA in the 
United States, each under a regional office 


FERC 


Federal Energy Regulatory Commission 
Federal Power Commission (now FERC) 


General Services Administration 


Department of Health and Human Services 


Management Information 
System 


Iffliaigration and Naturalization Service 

A computer-based organizational information 
system which provides data to support 
management activities and functions 


Matrix of 

Responsibilies 


National Resource 
Systesis 


A method of graphically relating agencies 
Co their respective areas of responsibility 

Memorandum of understanding 


The thirteen categories, defined in Figure 
2.2, potentially vulnerable to disruption 
by terrorism, civil disorder, sabotage, and 
subversion 


NEMS 


National Emergency Management System 
National Intelligence Estimate 
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NPP 

NRG 

NSA 

NSC 

OEO 

0MB 

PD 

POC 

POL 

Post-Event Recovery 
Phese 


National Preparedness Programs Directorate 
in FEMA 

Nuclear Regulatory Commission 

National Security Agency 

National Security Council 

Office of Emergency Operations in FEMA 

Office of Management and Budget 

Presidential directive 

Point(s) of contact 

Petroleum, oil, and lubricants 

The period of activity, following a civil 
security event, in which recovery 
o{>erations occur 


Pre-event Preparedness The period of continuous, on-going activity 
Phase in preparation for and prior to a civil 

security event 


Readiness Posture The capabilities for dealing with a 

contingency 


Responsibility Network The interrelationships and overlap among 

agencies' responsibilities 

SEC Securities and Exchange Commission 

S/D Scenario Dependent 


SLP 


State and Local Programs and Support 
Directorate in FEMA 


SNIE 


Special National Intelligence Estimate 


SS 


Secret Service 


Straw Man A technique used to test the applicability, 

relevance, and usefulness of a proposed 
central idea 
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WHSR White House Situation Room 

Threat Climate Appraisals of the likelihood, context, and 

form of terrorism, civil disorder, 
sabotage, or subversion 

Trana^event Response the period of activity during and 

Phase immediately following a civil security 

event in which Inmiedlate reactlon^r espouse 
measures are taken 

TVA Tennessee Valley Authority 
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